Secret Terrorist Watchlist with 1.9 Mn Records Exposed Online

Date:

Share post:

Sometimes, misconfigured servers and unsecured databases go unnoticed until security researchers report about them. Bob Diachenko, Head of Security Research at Comparitech, recently discovered an unsecured Elasticsearch server containing a terrorist watchlist of over 1.9 million records. The server was left online without any password protection, allowing anyone to access the information.

Diachenko stated that the watchlist belongs to the Terrorist Screening Center (TSC), an FBI multi-agency group. The TSC maintains a watchlist of suspected terrorists and no-fly members, which is a subset of a larger watchlist. Officials are authorized to access the watchlist and perform terrorist screening.

The exposed records contained confidential information such as full names, TSC watchlist ID, citizenship, gender, birthdates, passport number, country of issuance, and no-fly indicator. The database is now secured after Diachenko reported the issue to the Department of Homeland Security (DHS).

Potential Risks Involved 

While search engines like Censys and ZoomEye indexed the leaky server, Diachenko stated that he is unsure if any unauthorized party has accessed it. Since the exposed data belongs to the people suspected as terrorists, there could be severe repercussions if the data falls into the wrong hands.

“The terrorist watchlist is made up of people who are suspected of terrorism but who have not necessarily been charged with any crime. In the wrong hands, this list could be used to oppress, harass, or persecute people on the list and their families. It could cause any number of personal and professional problems for innocent people whose names are included in the list,” Diachenko said in a post.

Bob DiachenkoSpeaking exclusively with CISO MAG, Diachenko said, “While it is unknown what party was responsible for the exposure of this watchlist, one thing is clear – no matter what size is your organization and how well established is your security posture, there should always be a place for additional checkups using quite simple cyber hygiene rules.”

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

5th Edition MENA CYBER SECURITY CONFERENCE – RIYADH EDITION

Name: 5th Edition MENA CYBER SECURITY CONFERENCE - RIYADH EDITION Website: https://mena-cybersecurity.com/riyadh/ Date: September 8th, 2026 Location: Crowne Plaza Riyadh Palace,...

Cyber Security Expo

Name: Cyber Security EXPO Website: https://www.cybersecurityexpo.co.uk/cheltenham Date: September 10, 2026 Location: Cheltenham Racecourse, United Kingdom The Cyber Security EXPO is the only...

6th Edition MENA CISO SUMMIT – Dubai Edition

Name: 6th Edition MENA CISO Summit – Dubai Edition Website: https://mena-cybersecurity.com/ciso-dubai/ Date: September 30, 2026 Location: Millennium Airport Hotel, Dubai,...

Build the Pipeline, Not the Headcount

There's a principle in Taoist philosophy called wu wei, often translated as "effortless action" or "non-doing." It doesn't...